PT-2024-5979 · Mitel · Mitel 6800 Series+2

Kyle Burns

·

Published

2024-07-17

·

Updated

2025-05-04

·

CVE-2024-41710

CVSS v2.0

7.7

High

VectorAV:A/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, versions through R6.4.0.HF1 (R6.4.0.136)
Description A vulnerability in the Mitel SIP phones could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system. The vulnerability is being exploited by the Aquabot botnet, a Mirai-based malware, to launch DDoS attacks. The botnet is targeting Mitel SIP phones, including the 6800, 6900, and 6900w series, as well as the 6970 Conference Unit.
Recommendations Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, versions through R6.4.0.HF1 (R6.4.0.136): Update to a newer version that contains a fix for this issue, as the current version is vulnerable to argument injection attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Argument Injection

Weakness Enumeration

Related Identifiers

BDU:2024-06787
CVE-2024-41710

Affected Products

Mitel 6800 Series
Mitel 6900 Series
Mitel 6970 Conference Unit